code-projects.org
https://code-projects.org/artworks-gallery-in-php-css-javascript-and-mysql-free-download CVE-2020-28687
HIGH
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile
Record summary
CVE-2020-28687 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBArtworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit ProfileExploitDB exploitby Shahrukh Iqbal MirzaNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-28687 packetstormsecurity.com
https://packetstormsecurity.com/files/160095/Artworks-Gallery-1.0-Shell-Upload.html